Running it
You are holding somebody's private material
Storage decisions made casually in month one are the ones that go wrong in year two.
Guides on Running it: The admin that turns income into a trade
The moment you accept your first job you become the custodian of something a stranger would be distressed to see published. That is not a dramatic framing, it is a plain description of the file sitting in your downloads folder.
Nobody sets out to handle it badly. It goes wrong because the default behaviour of every device you own is to keep things forever, in several places, and to sync them somewhere you did not choose.
What you actually hold
Three categories, and they have different half-lives.
Submitted material. The photos, video or audio a buyer sent you. This is the only category with real exposure attached, and it is the one with the shortest legitimate lifespan.
Correspondence. Messages, briefs, scope discussions. Usually on the platform, sometimes exported.
Commercial records. Dates, fees, formats, what was delivered. No sensitive content, and the category you need for years rather than days - the case for keeping these is separate from everything else here.
The mistake is applying one policy to all three. Commercial records deserve a long retention and a backup; submitted material deserves the opposite of both.
Retention: the shortest period that still works
The only honest justification for holding submitted material past delivery is a dispute. Data protection law points the same way where it applies: the UK regulator's guidance on data minimisation says to periodically review what you hold and "delete anything you no longer need".
Most platforms close the dispute window somewhere between two weeks and ninety days after delivery. Find yours, and set your retention to that window plus a small margin. When it passes, delete.
| Category | Keep for | Backed up? |
|---|---|---|
| Submitted material | Dispute window plus a few days | No |
| Messages and briefs | Same, unless the platform holds them anyway | No |
| Fees, dates, formats | Years, per your tax rules | Yes |
| Your own templates | Indefinitely | Yes |
The "no" column is deliberate. A backup is a copy you have lost track of, and for the one category that must not proliferate, a copy you cannot enumerate is a liability rather than a safeguard. The backup discipline worth having covers everything except this.
Where it lives while you have it
One folder, on one device, with full-disk encryption switched on. Every current operating system ships this and it is off by default on nothing you would buy new; check yours today rather than assuming.
Then check what is syncing that folder. Photo libraries in particular will hoover up anything that lands in a watched directory and put it on a server, in a shared album, or on a family device. This is the single most common way earners discover they have distributed client material: not a breach, a default.
Do not open submissions on a shared machine. Do not forward them to yourself for convenience. Do not keep a "best of" folder for any reason - there is no version of that which survives being explained.
Deleting properly
Deletion has three steps and most people do one.
Remove the file, empty the trash, then check the places a copy quietly appeared: the messaging client's cache, the browser downloads folder, the thumbnail preview store, the cloud bin that holds deleted items for thirty days.
Set a recurring reminder rather than relying on intent. A monthly sweep of one folder takes two minutes and is the entire mechanism. It belongs in the daily and weekly admin loop rather than in your memory.
Never reuse a submission
Not as a portfolio piece, not as a public worked example, not cropped, not blurred, not "with permission" obtained casually in a message.
The reason is not squeamishness, it is that consent to be assessed is not consent to be published, and the two get conflated constantly. If you need a public example, build it on generic material nobody owns, which is what the worked example post is about.
Aggregate observations are fine. "Most submissions arrive with poor lighting" describes your work, not a person.
What the platform carries and what you carry
Platform terms typically cover the platform's own handling of the material and say very little about what happens on your machine after download. Read yours once, properly, so you know which half of the problem is yours. Where a platform states its own handling rules for judges, that statement is the boundary of what it takes responsibility for, and Rate Cock's is on its judges page.
Buyers, for their part, are increasingly deliberate about this - the buyer-side account of what happens to a submitted image is a better description of their expectations than anything you will infer from a brief. Where a job involves any kind of measurement or numeric record rather than a picture, the conventions for handling that data are the reference, and they are stricter than most people assume. Automated services face the same question at a different scale, and how automated assessment handles retention is worth reading precisely because their answer is public and yours is not.
The practical test is simple. If a buyer asked, today, exactly what you still hold of theirs and where it is, could you answer in one sentence and be right? If the answer is no, the fix is not a policy document. It is one folder, one reminder, and encryption switched on before the next job lands.